CaseLeadCaseLead
Security & compliance

The security whitepaper — written for the people who have to approve it.

This page is for your IT security lead, your CJIS Systems Officer, and your legal reviewer. It states CaseLead's trust boundaries, controls, and compliance posture plainly — what we enforce, what we document, and what is honestly still in progress. Print or save it as PDF and put it in the file.

Our design rule is the same one your evidence room runs on: custody is only real if you can prove it. Every control below exists to keep case data in agency custody, keep the record intact, and keep every action accountable.

1 · Deployment models and the trust boundary

CaseLead deploys three ways. The security story differs by model, so we state each boundary explicitly rather than averaging them into marketing language:

Agency facility & CJIS boundary — air-gapped deployment
Ingest & processingVision, speech-to-text, and document parsing — all on-device
AI modelsLocal language and embedding models on agency hardware — no external API
Case store & indexEncrypted at rest; evidence originals read-only, SHA-256 verified
WorkstationsAgency clients on the agency network; RBAC + MFA at the application
Audit trailImmutable log of user and system actions, retained on-site
BackupsEncrypted, verified, restored on your media, in your custody
⛔  Crossing the boundary in air-gapped mode: nothing. No cloud, no vendor telemetry, no model API, no update phone-home. Updates arrive as signed media you carry in (see §6).

2 · Data protection

3 · Identity & access

4 · Audit & accountability

5 · AI-specific safeguards

These are product rules, stated in full on our Responsible AI page, that matter to a security and legal review:

6 · Software supply chain, updates & vulnerability handling

7 · Backup & recovery

8 · Compliance status

We state certification status honestly — "documented" and "planned" mean exactly that. We are skeptical of vendors who imply certifications they don't hold, and we won't do it.

ItemStatusDetail
CJIS Security PolicyDocumentedControl-by-control mapping maintained against the current CJIS Security Policy; walked through with your CSO/ISO during procurement. CJIS compliance is a property of the whole deployment (§10), so the mapping is finalized per site.
Section 508 / AccessibilityPublishedVPAT (accessibility conformance report) and accessibility statement are public.
Vulnerability disclosurePublishedPolicy + security.txt.
Independent penetration testIn procurementThird-party penetration test of the hosted platform is being procured; internal security review findings are remediated on a priority basis. Results summary available to customers under NDA when complete.
CryptographyDocumentedAES-256-class encryption at rest (LUKS), TLS 1.2+ in transit, SHA-256 evidence integrity, Ed25519 release signing. Formal FIPS 140 validation status of deployed modules is addressed per deployment during procurement.
SOC 2 Type IIPlannedApplies to our hosted (non-CJI) environment; timeline available on request. Air-gapped deployments run entirely under agency controls.

9 · Shared responsibility

CJIS compliance is a property of an entire deployment — hardware, network, facility, personnel screening, and agency policy — not of any single product. CaseLead is built to operate inside a CJIS-compliant environment and to make that posture the default: we bring the application-layer controls above and the documentation to map them; your agency brings the physical, personnel, and network controls it already operates. During procurement we produce a deployment-specific packet: your hardware sizing, your control mapping, and acceptance criteria you can test against.

10 · Questions your reviewers will ask — answered

Need the deployment-specific version? This page is the current general whitepaper — print or save it as PDF for the file. For your agency's version (hardware sizing, site control mapping, acceptance criteria, package documentation under NDA), request it through the contact form — or go straight to a 30-day evaluation and test the controls yourself.

← Back to caselead.ai